audit Àû¿ë¹ý
# vi /etc/audit/audit.rules¸Ç ¾Æ·¡ ´ÙÀ½ ¶óÀÎ Ãß°¡-a entry,always -F arch=b64 -F uid=0 -S execve -w /sbin/reboot -w /sbin/shutdown -w /sbin/init
ÀúÀå ÈÄ # chkconfig auditd on # service auditd restart